Blog
CVE-2026-76460 (CVSS 10.0): Cisco ISE Authentication Bypass Gives Attackers Root Access — Your Zero-Trust Backbone Is Under Attack
CVE-2026-76460 is a CVSS 10.0 authentication bypass in Cisco ISE actively exploited since Sept 16, 2026. No workaround exists — patch now or risk your zero-trust policy engine falling to…
Read More →APT36 Operation RapidRust: Transparent Tribe Deploys Rust Backdoor Against Indian Government — Zero Trust Is Your Only Firewall
APT36's Operation RapidRust targets Indian government with RUSTYSHADE—a Rust backdoor using GitHub C2. USB air-gap tool RUSTYMOVE also deployed. IoCs inside.
Read More →WaterPlum (DPRK): North Korea’s AI-Powered Fake Job Interviews Have Compromised 30,000 Developer Devices — Is Your Team Next?
North Korea's WaterPlum group infected 30,000+ developer devices in 100+ countries via fake job interviews, stealing $10.7M in crypto. FBI advisory Sept 18, 2026.
Read More →CVE-2025-25249 (CVSS 9.8): Fortinet FortiOS CAPWAP Zero-Day Weaponised by PivotC2 RAT — 178 Firewalls Compromised and Counting
CISA adds CVE-2025-25249 to KEV: Fortinet FortiOS CAPWAP heap overflow (CVSS 9.8) exploited by PivotC2 RAT on 178 firewalls. Patch now.
Read More →CVE-2026-83548 (CVSS 10.0): SonicWall SMA1000 Pre-Auth SSRF Chained to RCE — Your Remote Access Appliance Is Under Active Attack
SonicWall SMA1000 zero-days CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 are actively exploited. Unpatched appliances allow unauthenticated RCE. Patch to build 12.4.3-03526 or 12.5.0-02952 immediately.
Read More →Microsoft September 2026 Patch Tuesday: Record 974 CVEs, Two Exploited Zero-Days, and a Silent Exchange Attack That Needs No Click
Microsoft September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited Windows zero-days and CVE-2026-55007, an Exchange Server unauthenticated RCE triggered by a single email. Action guide for…
Read More →CVE-2026-58704 (CVSS 8.0): Google Pixel Zero-Click Modem Exploit — Federal Patch Deadline Today, CISA Orders Emergency Action
CVE-2026-58704 is a zero-click modem exploit on Google Pixel 6–11. CISA added it to KEV on 16 September — federal patch deadline is today. Patch now.
Read More →Firewall Policy Audit in India — the Rules Nobody Dares Delete
The rule base nobody wants to touch Every firewall I open for the first time tells the same story — not of the network as it exists today, but of…
Read More →SEBI CSCRF Consultant — Getting a Regulated Entity Audit-Ready
The framework that changed the conversation for every SEBI-regulated entity Since SEBI issued the Cyber Security and Cyber Resilience Framework on 20 August 2024, my phone has rung differently. It…
Read More →DPDP Act Consultant — What India’s Data Protection Law Actually Demands of Your Network
DPDP Act 2023: the part nobody tells you Over the past year, more and more conversations with CIOs and founders across Delhi NCR have started the same way: “Our lawyer…
Read More →